The only supported version is the latest from the master and develop branch. All other versions will NOT be supported.
Do not submit an issue or pull request: this might reveal the vulnerability.
Instead, you should contact Polyfrost directly at our discord server, in a ticket.
We will deal with the vulnerability privately and submit a patch as soon as possible.
You can also submit your vulnerability report to huntr.dev and see if you can get a bounty reward.